Data Processing Agreement
Last updated: July 9, 2026
Last updated: July 9, 2026.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between EvaAI, operated by Gustavo Zermeno P., operating commercially as EvaAI, with domicile in Leon, Guanajuato, Mexico ("Processor" or "EvaAI"), and the customer using the EvaAI platform ("Controller" or "Customer").
This DPA governs the processing of personal data by EvaAI on behalf of the Customer in connection with the Services.
This DPA is available in English and Spanish. In case of conflict between language versions, the Spanish version shall prevail.
Contact: Message us on WhatsApp
1) Definitions
- "Controller" means the Customer who determines the purposes and means of processing personal data through the EvaAI platform.
- "Processor" means EvaAI, which processes personal data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person whose personal data is processed.
- "Personal Data" means any information relating to a Data Subject, including message content, contact information, and metadata.
- "Sub-processor" means a third-party service provider engaged by EvaAI to process personal data on behalf of the Controller.
- "Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
- "LFPDPPP" means Mexico's Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares.
2) Scope and Purpose
EvaAI processes personal data on behalf of the Customer solely to provide the Services described in the Terms of Service. This includes processing message content, contact information, conversation history, and related metadata across the messaging channels connected by the Customer (WhatsApp, Instagram, Messenger, web chat).
The categories of data subjects include the Customer's end-users, contacts, and leads who interact with the Customer's AI agents through the EvaAI platform.
3) Customer Obligations
As the Controller, the Customer is responsible for:
- Ensuring a lawful basis exists for the processing of personal data through the EvaAI platform.
- Providing appropriate notices to end-users about how their data will be processed.
- Obtaining any required consents from end-users before connecting messaging channels.
- Ensuring that instructions provided to EvaAI for data processing comply with applicable data protection laws.
- Responding to Data Subject requests related to their personal data.
4) EvaAI Obligations
As the Processor, EvaAI shall:
- Process personal data only on documented instructions from the Customer, unless required by law.
- Ensure that persons authorized to process personal data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures.
- Assist the Customer in responding to Data Subject requests.
- Assist the Customer in ensuring compliance with data protection obligations, including breach notification and data protection impact assessments.
- Delete or return all personal data upon termination of the Services, subject to the retention periods specified in the Terms of Service.
- Make available to the Customer information necessary to demonstrate compliance with this DPA.
5) Sub-processors
The Customer authorizes EvaAI to engage the following sub-processors to assist in providing the Services:
- Supabase (database hosting and storage) - United States
- OpenAI, Anthropic, and Google Gemini (AI model providers for agent responses) - United States
- OpenRouter (AI model gateway and routing) - United States
- Meta Platforms (WhatsApp, Instagram, Messenger messaging delivery) - United States
- Twilio (voice and SMS communications) - United States
- Stripe (payment processing and billing) - United States
- Vercel (frontend hosting and delivery) - United States
- Koyeb (backend hosting and compute) - United States / Europe
- Upstash (Redis caching and job queues) - United States
- Facturapi (Mexican electronic invoicing / CFDI) - Mexico
- Google (Calendar integration and OAuth) - United States
- SendGrid (transactional email delivery) - United States
Changes to Sub-processors
EvaAI will notify the Customer at least 30 days in advance before adding or replacing a sub-processor, via email to the account's registered address. The Customer may object to the change by contacting privacy@goeva.ai within the notice period. If the objection cannot be reasonably resolved, the Customer may terminate the affected Services.
All sub-processors are bound by data processing obligations no less protective than those in this DPA.
EvaAI shall ensure its sub-processors comply with equivalent data protection obligations. EvaAI's aggregate liability for the acts and omissions of its sub-processors shall not exceed the limitations set forth in the Terms of Service.
6) Data Transfers
Personal data may be transferred between Mexico, the United States, and other regions where EvaAI's infrastructure or sub-processors are located.
Where required by applicable law, EvaAI ensures appropriate safeguards are in place for international data transfers, such as Standard Contractual Clauses or equivalent mechanisms recognized under the LFPDPPP.
7) Security Measures
EvaAI implements and maintains appropriate technical and organizational measures to protect personal data, including:
- Encryption of data in transit using HTTPS/TLS.
- Encryption of data at rest using AES-256 for database storage.
- Access controls with least-privilege principles.
- Regular monitoring and audit logging of data access.
- Secure infrastructure with managed database services.
- Employee confidentiality obligations and security training.
8) Data Breach Notification
EvaAI will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach that affects the Customer's data.
The notification will include:
- The nature of the breach, including categories and approximate number of Data Subjects affected.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach and mitigate its effects.
- Contact information for EvaAI's point of contact for further inquiries.
Cooperation
EvaAI will cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach. EvaAI will also assist the Customer in meeting any breach notification obligations under applicable law.
9) Data Subject Requests
EvaAI will assist the Customer in responding to Data Subject requests to exercise their rights (access, rectification, deletion, objection, portability) by providing appropriate technical and organizational measures.
If EvaAI receives a request directly from a Data Subject, EvaAI will promptly redirect the request to the Customer, unless legally required to respond directly.
10) Data Retention and Deletion
EvaAI processes personal data for the duration of the Customer's subscription. Cancellation honors the paid period; when the subscription terminally ends — at the end of the paid period, or after payment retries are exhausted following a failed payment — the account is paused.
While paused, personal data is held in a reversible state so the account can be reactivated. Approximately 150 days after the pause, if the account has not been reactivated, EvaAI permanently and irreversibly deletes conversations, contact and message personal data, media, and knowledge-base content, and disconnects the messaging channels. Database backups containing that data are purged in the ordinary course of EvaAI's backup rotation.
Fiscal and billing records, including Mexican electronic invoices (CFDI), are retained through EvaAI's invoicing sub-processor for the period required by Mexican tax law (approximately five years), even after other personal data is deleted.
Before permanent deletion, and upon request at any time, the Customer may export its data (see Section 15). The Customer may request a certification of deletion by contacting privacy@goeva.ai after the deletion period has elapsed.
11) Audit Rights
The Customer may request documentation demonstrating EvaAI's compliance with the obligations set forth in this DPA. Requests should be directed to privacy@goeva.ai with reasonable advance notice.
EvaAI may satisfy audit requests by providing relevant certifications, audit reports, or written summaries of its security and data protection practices. On-site audits may be arranged upon mutual agreement, at the Customer's expense.
Audit requests are limited to once per twelve-month period, unless required by a data protection authority or following a confirmed data breach.
12) Mexican Data Protection Law (LFPDPPP)
EvaAI complies with Mexico's Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (LFPDPPP) and its regulations.
EvaAI supports the Customer in fulfilling obligations under the LFPDPPP, including:
- Supporting ARCO rights (Access, Rectification, Cancellation, Opposition) requests from Data Subjects.
- Maintaining appropriate privacy notices as required by the LFPDPPP.
- Implementing security measures consistent with the LFPDPPP's requirements.
- Cooperating with Mexico's National Institute for Transparency, Access to Information and Personal Data Protection (INAI) when required.
13) European Data Protection (GDPR)
Where personal data of individuals located in the European Economic Area (EEA) or the United Kingdom is processed under this DPA, the following additional provisions apply:
- The Standard Contractual Clauses (Module 2: Controller-to-Processor) approved by the European Commission are incorporated by reference and apply to international transfers of EU personal data.
- Data Subjects in the EEA have the right to data portability, the right to erasure, the right to restrict processing, and the right to lodge a complaint with their local supervisory authority.
- EvaAI will process EU personal data only in accordance with documented instructions from the Controller, consistent with the requirements of GDPR Article 28.
- The applicable Standard Contractual Clauses are available upon request by contacting privacy@goeva.ai. EvaAI will execute the SCCs with any Customer upon written request.
14) Liability
Each party's liability arising under this DPA is subject to the limitations of liability set forth in the Terms of Service.
Nothing in this DPA limits either party's liability for willful misconduct, gross negligence, or violations of applicable data protection law.
15) Term and Termination
This DPA is effective for the duration of the Customer's subscription to the Services and remains in effect until all personal data has been deleted or returned in accordance with Section 10.
Upon request prior to the start of the deletion process, EvaAI will provide the Customer's data in a commonly used, machine-readable format (e.g., CSV or JSON).
The obligations in this DPA survive termination to the extent necessary to fulfill data processing and deletion obligations.
This DPA is governed by the same law and jurisdiction as the Terms of Service (federal laws of Mexico, courts of Leon, Guanajuato).
Schedule A — Shopify Integration
This Schedule supplements the DPA when the Customer connects an external Shopify store to EvaAI. It documents the personal data EvaAI processes via the Shopify Admin API, the purpose, the categories of Data Subjects, and the retention applied.
Categories of Personal Data Processed
- Customer identity: name, email address, phone number, default shipping/billing address (only when the Customer has been approved for Shopify Protected Customer Data Access Level 2).
- Order data: order number, status, line items, totals, shipping and tracking events, and the email address provided at checkout.
- Draft order data: line items and customer association created by EvaAI on the merchant's instruction in response to an end-customer request.
- Catalog data (non-personal): product titles, descriptions, prices, variants, images, inventory levels, store locations.
Categories of Data Subjects
- End-customers of the Customer's Shopify store who initiate a conversation with the Customer's EvaAI agent through WhatsApp, Instagram, Messenger, or web chat.
Purpose of Processing
EvaAI does not use Shopify-derived personal data for advertising, profiling, automated decision-making with legal effects, model training, or sale to third parties.
- Answer end-customer product, pricing, and stock questions on behalf of the Customer.
- Look up an existing order or recognize a returning customer when the end-customer self-identifies in chat by email or phone.
- Create draft orders or send checkout links when the end-customer requests them.
Source of Data
- Shopify Admin GraphQL API (initial bulk import + nightly reconciliation).
- Shopify webhooks subscribed at install time (`products/*`, `inventory_levels/*`, `orders/*`, `customers/*`).
- Shopify GDPR compliance webhooks (`customers/data_request`, `customers/redact`, `shop/redact`) — handled within 30 days of receipt.
Retention
Active connection: data is refreshed via webhooks and a nightly reconciliation job and retained while the connection remains active.
Disconnection: all Shopify-derived rows for the affected store (products, customers, orders, draft orders, locations) are deleted within 90 calendar days of the disconnect event. Database backups containing those rows are purged within 60 additional days.
GDPR webhook events (`customers/redact`, `shop/redact`): the affected rows are deleted within 30 days of the webhook receipt.
Security Measures Specific to Shopify
- Access tokens (Partner-issued or merchant-issued custom-app tokens) are stored encrypted at rest using AES-256-GCM with per-row authenticated additional data (AAD).
- Webhook payloads are HMAC-verified using the Partner client secret before any database write.
- Outbound API calls to Shopify use TLS 1.2+ and per-store rate-limit budgets.
- Operational logs containing Shopify customer PII are written only at WARN/ERROR severity and rotated according to EvaAI's standard log-retention policy.